CVE 7.1 HIGH

CVE-2025-64134_CVE-2025-64134

7.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Description

Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.

Basic Information

ID CVE-2025-64134
Source jenkins
Published Oct 29, 2025 at 13:29
Modified Oct 29, 2025 at 14:08

Affected Product

Vendor Jenkins Project
Product Jenkins JDepend Plugin
Affected Versions Jenkins Project Jenkins JDepend Plugin 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.